#general
1 messages Β· Page 192 of 1
you will get pressed hard by people more confrontational than myself
CJCA CWES and then CPTS
Cuz CWES is easier than CPTS it will make things easier for you
Well of they authorized you
But if it just was words
ILLEGAL
You know
in bullet points, tell me what red teaming is
Idk if that's a good plan tho..
Bro under no circumstances are you to exploit a vuln you know to exist
I need both blue and red knowledge for it and I will lack blue knowledge
Report the vuln and move on
You probably want some signed paperwork that allows you to do that
That's the goal to get tomorrow
A little bit is not illegal
???
just kidding
thats what she said π
-# (well at least a modified version of it)
Illegal is illegal 
The law doesn't suggest you can do just a little crime and have it be fine TF dude lmao
@rustic carbon
Exploit could mean being able to finding another one
everyday in here i swear
you kids are fucking annoying
Kinda like a cyber swat I heard


no?
classic clip from Dumb and Dumber

I don't believe that to be correct sir
Aaaah
btw SWAT stands for Special Weapons and Tactics
dude focus on learning rather than yapping here π
Having more knowledge than a pentester... making viruses, exploiting webs, networks... overall a menace kinda π
-# thats what I heard
Dude I'm so fucking excited and filled with blood rush rn
Means doing apt install on ubuntu terminal in starbucks while wearing tactical gear
Tomorrow its late now 
A red team is comprised of pentesters
Vro
Just to uh throw that out there
You can change your grades
then go sleep or you will get bullied
-# (i will be the one to bully you)
Irl pentest are actually like HTB I can't fucking believe it
Please don't get ideas from me
lets just have you forget what you just said entirely. The main point of red teaming is emulating real-world threats. Its not james bond shit, 99% of the time
Well da xd
That should be your first accual step in real bug bounty hunting
Dude I'm not joking, I'm filled with a bloodrush rn
That's such horseshit stupid advice
This is so crazy
Dude Im not 5 to sleep at 10pm 
Are you guys really this stupid?
Yes they are
I am
What
Stop dropping reverse shells on vulnerable targets
this line proves you are 5 π
Ok now that sound even more appealing 
My guy, I have authorisation π
TO FIND A REPORT A VULN
Please if someone gets any bad advice from me keep in mind I am stupid
@meager kernel before reporting anything, you said you have authorisation to do so, make sure you get it in WRITING, with clearly defined scope
I am too
Otherwise you may well find yourself thrown out
CAN I NOT FIND THE FULL EXTENT OF MY VULNERABLILITY
*in
-# (thrown in the jail)
And then the children learned about what Scope is
Yes sir
SCOPE
Damnnnn
Just because your tutor said it was ok does not mean the whole dept responsible for the platform is in agreement
Seems fun in here rn
All you need to know about red teaming and tradecraft in general is this acronym: TTP (Tactics, Techniques, Procedures). Everything else you said is still just pentesting. Red teaming is an exercise typically between defenders and attackers. Focus on becoming a pentester then you can attempt to gain skills for tradecraft
(thrown out of the course)
(but yes also maybe I guess?)
Alright, I'll get everything sorted tomorrow, then do rest of the bug hunting
well he will be in a quantum state where he is in and out at the same time π
Yo you have done your homework I see.. 
Yee sounds about right
Make sure you ask it clearly that your TUTOR has the power to authorise such testing too
My homework? sure..
Lol
Just because they said you can, doesn't mean they can allow you to
@eternal mango dude, I can't believe it but irl bug hunting is so much like HTB
You know what I mean π
It can be fun
If you can call years of experience in the field "homework" then sure
and traumatising
You can do that with only one ip?
My college has zero firewall protection π§ββοΈ
And duplicated 
That can't be true lol
Thatβs tuff
Yes, my college server operates on one IP
There's like 3 ports on it
Okay I just need a refresher, the majority of chatters right now are non-american correct?
Ay
Server singular?
that's crazy
Pretty sure
I even struggle with English
The main college website operates on HTTP but there's a hidden unreleased environment on HTTPS
whats the matter with non Americans ?
You, cloud and myself ik are American
I think most of us are european..
Do they not teach ethics in other countries relating to cybersecurity? You guys are embarrasing your home countries
He never said there is anything wrong??
Yep 99%
No
fixed
Yikes
I don't even have a degree in cybersecurity
And I am not an American
They don't have cybersecurity near their vocabulary around here
π
That didnt help 
Indeed
i am not American habibi
Dang right
Iβm gonna start an anon revival
Give me ze Bebsi
It doesn't take a degree to have a strong base of ethics
I dont think anyone is american here
Who wants to be part of a cyber activist group !
Nor does it take a degree to have a strong base of experience or skill in.. well, any field
i won't give you za bebsi you sdubid its my bebsi
When did you start cybersecurity??
A few of us are, the ones arguing with you guys on ethics...
Goblin am I getting too old for this
If you say we started at the same time Im gonna be pissed
π₯

Anyway, just get clear and documented permission from not only your tutor, but the college head too.
Then go to town, and stay IN SCOPE
π€£
anyways guys i will brb after eating za shawarma
Good boys stay in scope
The children need to learn the ways
Men with goth GFs stay in scope
And 100% that scope will not include sharing details of your colleges vulnerabilities in DM with randos
I used to warn my clients about RCEs and SQLIs when I read the source code, they never care so I just try to do my job as best I can and move on
Can I take a bite

sure my friend
The legal team would never sign off imo
mmhmn
Cybersecurity is not "hrr drrr im hAcKiNg!!" its:
- permission from 5+ people
- a well-defined scoped engagement that took months to come to agreement on
- tons of liability
- 99% reporting
you guys are annoying
Too much risk and liability
yarp
If I see another PDF converter malware I'm gonna throw up
haaahah
thank you for za complement my friend
If it wasnt for the active directories burning me out 
YOU WERE!
end users are stupid
I did IoT pentesting for south korean products, when i submitted the report they fought with me on whether or not CVSS scoring was REAL
Issue rests on its fat ass between keyboard and chair
You ever test a product from supreme?
Ik ik
i will never tell you what products ive pentested
I was abt to say
Samsung galaxy s24
Test the supreme brick
Probably drones
My favorite physical testing tool
Anyway, tldr nice work, but be careful. Not everyone is as open as your tutor, and your tutor unlikely has authority to permit such intrusive testing.
One fuck up can ruin your future career perspectives
Penetration test a .50cal
Your tutor is certainly a moron
50.caliber
take his advice with grains of salts
ESPN !!!
And I doubt having permission from them would matter
Since I doubt a reasonable person would expect a tutor to have the capacity to give it
Or the ability to bind the college to an agreement
mm binding
Its like stealing a car and saying that the guy next to the car said it was his and you could have it
Yes sir I understand
My plan is to go tomorrow and get permission from the college dean for this
I think that has a more clear cut case though
If you go to your dean and they are like "YOU DID WHAT?"
Then I'll perform the full bug hunt and report it
One could reasonably believe it was their car
Focus on your college work
@meager kernel if your tutor doesn't take responsibility you go to jail
Pink cuff bindings
Ima be real chief, theyβre going to tell you no
Itβs too much liability and risk
No no, ofc not, I'll go to my Head of Department first and then talk to him
If you get extra time and permission to test things, great.. but just.. no, be careful
Yeah the IT department of the college is not a huge fan of students pentesting things without permission
Rev shell = jail
Hopefully not
Source: I was this guy
They will not give a contract for you to test the college infra
Ik
Do you have liability insurance?
You are more likely to get kicked out, even with best intent
lmfao he doesnt even know what liability means
It means you're responsible for damages π
elowel
Just trying to help you avoid a mess 22Kratos
Uhhhh
Yes sir
I understand
Take it easy he is trying to do a good thing
It's easy to do things like that with the best intent, but also easy to get in to a mess if you do not have legal permission and experience to understand limitations and liability
It's just I got so excited cause I did a real life bug hunt and it felt so good ππ
We're trying to help protect them D3v
we'll put money on your books
thats not how it works
Letting a college student fuck around with a production network, containing legally protected data and other PII is just a recipe for disaster
And they get 0 value out of it
I know brother
No one would let a student do that
You could easily be turned into a scapegoat too if something goes wrong
e.g. take down a critical system by mistake
this is why i can never go back to blue team, in any capacity
I made some college kids shit their pants when I had to approach them and ask why they had pentesting tools on the desktop of one of my hosts.
fuck these kids man, i am fully demoralized
Eh this is just common kids
I get how you could not understand this stuff
its so much worse than any of us think
how did they install in the first place, should have denied install access
Cause to them itβs just poking around and learning
Yes sir
And not thinking of the risks involved
I will be careful
You guys make blue team like it's mining 
Sorry I got a bit excited rn π π
Installation =/= downloads
If you donβt know the risks itβs hard to evaluate
If you're after a real target to practice on
im not going to argue about the doomed kids, i am going to say they cant read
on our hosts, no one can download anything without admin access
You kinda make me afraid to actually pentest if the time comes bro damn π₯²
download or install
Hi guys
https://www.youtube.com/watch?v=zN8OjHgNevo This for brath
Provided to YouTube by Vydia
Demoralization of the Luminary Β· Aristeia
Demoralization of the Luminary
β 2013 Mediaskare Records
Released on: 2013-12-31
Composer: Aristeia
Auto-generated by YouTube.
Hmmm I'll check that out too
Full demoralization
Places like schools and businesses have to balance security with accessibility.
When the time comes, you will have the appropriate contract and legal knowledge, or be working as an employee for a company that handles that.
you SHOULD be
its not supposed to be mr fucking robot
Yeah corpo legal handles this stuff
Itβs why doing independent work is risky
It's only scary if you're doing it on your own with no guidance or backup at all lmao
You actually have to have a lot of weight on your shoulders to pentest I see..
Damn
Alright interesting
Yup, I meant independant vs company work
Some computers if you break it people die
You can do independent work too?
Developers nowadays use ai for making thier websites and apps so there will be valnurabilities
PARDON? π
i do not want anybody but the best, most ethical, and stable people in this industry defending our future
Hospitals and factories
Factory equipment is deadly when it breaks
if you are near them tho
if you run nmap in a SCADA environment you are going to destroy alot of shit
Yes but you don't wanna hurt other people
hello im new to this
no
Not really... it's pretty easy, understand scope and liability, stick to it. If you want to work under contract with clients, you do need understanding of drawing contracts and covering yourself regarding damage. If you work for a company as a tester, they will handle most for you on that side, but it's still down to you to stay in scope
Power plants
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Any ICS really
The list goes on and on yeh
Well no shit that's why Im in htb and not tor rn 
Yep
oh alr tought im the only one
@zealous island
thanks i apreaceate it
I know someone who bragged to me about going into a neighborβs weather station because admin creds were defaulted like I was going to give him a pat on the back.. now i monitor his workstations even harder.
Can I work independently too?
As a red teamer
Yes
But you shouldn't as a first go at it lol
its alot of work. get a corpo job first son
Will that make more profit?
real
Yes, but if you do as I said you need an excellent understanding of contracts, scope, liability, insurance, etc etc etc
Depends
not for a long time
You have more upside, but also more risk and overhead
No @harsh elm
bruh why is there soo much async rat malware going around????
I mean after I finish CJCA CPTS OSCP and other certs I think I would have a good understanding of them already
πππwhy
When you work for someone they take alot of the risk on
This is a server for Hack The Box, a platform to learn. We're not here to provide hacking services.
Compared to you doing it yourself
You go a lot in greece Idk if you know about it too π₯²
if you get CPTS (harder than OSCP) you are ready for a entry-mid level pentesting role.
Oh okay
Iβm not Greek, but there is some Greeks around
Just kidding
But but the red rooms
The fuck am I reading
(/s)
@eternal mango alright, so my plan is, to go tomorrow and tell my Head of Department that I found a vulnerablility (he said to me earlier that I'm allowed to find vulns and report them), and then tell him to get me a written letter by the higher ups so that there's no action against me and I can safely give a whole write up
Good plan or bad plan?
idk I just got here
kids these days
Well.. yes and no
Yee I know you are not greek (Im MrHolmes if you dont remember haha) I'm just saying because (I think) you are one of the heads in this platform that you know about it... I could be wrong 
Adult kids 
How do you get that font in your name?
Ask for the letter of auth first, do not mention any findings
What should I change?
Iβm just the community person
I'm just cloud
G0blin is more of a head person lol
are any germans here ?
But honestly, you will not get a letter of auth from the college in a legally binding matter
wunderbar
Yes yes, I won't mention what findings I got, I just want the letter of permission
it's in the options on discord to change your username font
If you do, great.. but come on
I think it's nitro only tho
Be. Careful.
Oh okay..
Even professionals mess up
You are in college to learn, focus on your colelge work
Thatβs what insurance is for
the amount of failure you will experience will be overwhelming
Goblin would you like a Christmas tree snack cake
It's not even December yet
Burn it

I'd love a conifer biscuit though
Yeah g0blin I remember him the one that helped me in the past when I first got in the server 
I am
Half debating moving there, wdyt of it
Youll do well here
there's also a bunch of Mirai going around too
Portland area was the thought lol
I can see you joining our hackspaces pretty quickly
@eternal mango is it natural to feel an adrenaline rush when you find some bug
yeah, youll fit right in
I presume rent is mad
Ofc bro you achieved something no one can do in your college lol
what do you think
Not bad in Missouri
Yes sure, but try not to get too excited. It can cloud your judgement, cause you to become careless
Keep your composure
Or compared to Canada
CLOUD YOU SAY
It's just that it's such a small vulnerability, but I knew of it cause I solved a HTB machine WHICH IS VERY SIMILAR
I am not sure what rents are right now, but portland is great because you can live along the trimet / train and get to portland under 40 minutes at the farthest parts
and it reaches super far
G0blin do you know anything about the gr cybersec markets?
Or no?
chat, I think Mozi might be a slight problem 
Isnβt there also Amtrak to Seattle and Vancouver
yes there is
GR no not really, I'm in the UK, sorry
Imagine an easy machine being the equivalent of my college security ππ
goes all the way to alaska
Based
My old roommate moved out there a few years ago from midwest and hasnβt looked back since
No it's okay I was just asking π
Yes sir
Eh, still waiting on USCIS to do their job but ty for info
if you end up moving ill happilly get you introduced to all the cyber folks here
northwest is best
Yeah appreciate it, itβs still a bit out
Need my green card first
Mind if I dm?
no problem
I was told the state public jobs out there pay decently enough. True?
they pay alright
a sweet one too
Freddo is life
the majority of ICS work i do is through state programs
No thank you
avg contract is 10k
Ew sweet?!
You have tried one there?
agree!
Iβm trying to stay in a public role unless something swings me private. Them PTO benefits are nice.
Yes many times
If I went to EU Iβd honestly goto like, Portugal or UK
Easy visa
Yes, black coffee is the only way
I've never once there been asked if I want sugar in freddo
It's always black
Just got a call from my cousin. She's like I got drunk and uninstalled what's app and now I reinstalled it but I can't remember my password. Can you hack it? I'm like I don't do that. Sorry. WTF man.
Maybe there's the expectation of you asking for it instead I guess
You sure are a tough guy because I would never wake up drinking a black coffee π
It tastes like battery acid for me
If you say so
I don't know how adding sugar to something would make it healthier
Overall sugar isnt good to digest on a huge amount that's why π₯²
I like my sweeteners artificial made by man!
Imagine drinking a sweet coffee plus something sweet after lunch etc etc
thank god I dont eat a lot of sugar except my coffee 
can someone help me to learn the basics ?
This is a normal day in america
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
@rustic carbon
We can help you help yourself
Yee
I rarely eat anything sweet these days tbh
The odd treat now and again if the daughter asks for a pastry or something from the shop
Otherwise yeah, most of my sugar comes from πΊ π
Beer?
That's what I said, yeah
Ohhh right
That's why beer makes you fat
alcohol is interesting. Maybe I'm drinking stuff that's too strong but it's kinda meh
Beer belly
I like a good stout
especially cocktails
I tried once at a bar a mango cocktail and I never got another cocktail again lol
i have an question. im currently learnin on academy.hackthebox.com but there is hackthebox.com whats the diffrence?
it's explained in the getting started module
I think hackthebox.com is just the main menu to choose between academy and labs lol
you just learned about subdomains
and the academy one?
pretty sure it's explained in literally the first module on academy
These been a few cases of malware and malware like situations on Linux recently and rather than doing separate videos it makes to merge a few of these topics together.
==========Support The Channel==========
βΊ Patreon: https://brodierobertson.xyz/patreon
βΊ Paypal: https://brodierobertson.xyz/paypal
βΊ Liberapay: https://brodierobertson.xyz...
Hey, anyone up for taking a look at some of my bug bounty reports (not fully reviewed yet) and giving me honest feedback on which ones are likely to be accepted or rejected?
Iβve got a few vulnerabilities (info leak, unauthorized access, open redirect/SSRF, etc.) and just want an objective opinion before I submit them.
no
Someone might steal 'em
feed them into a chatbot, that would take forever for us to review and i have no idea who you are
pretty sure it's also against the whole disclosure process too 
Alright broskis Imma peace out now
Talk to you guys this Friday again 
Going MIA to finally finish this damn module once and for all
see ya
@eternal mango btw thanks alot man
I was getting a bit too excited
Might've done a mistake
proud of you for admitting it
I'll tread carefully and report it responsibily
Firstly I'll get a written permission for all this
@exotic pendant friday -5
The chatbot is always on the userβs side.
warm beer π©
ewwwwwwwwww
Brilliant and insightful sketch aimed squarely at Gordon Ramsey and the hordes of cookery shows on British television.
Do Mitchell and Webb a favour and buy their DVD for someone this Christmas. :)
A Balrog of Morgoth
hi
https://jh.live/rekcah || Snag a copy of THE FUTURE IS ****** comics, Backdoors & Breaches, and tons of other sweet stuff at the Spearphish General Store! (not a phish) https://jh.live/rekcah
Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training
See what else I'm up to with: https://jh.live/newsletter
βΉοΈ Affilia...
its intresting
why the fuck is discord lagging as fuck
freezing every 2 sec when typing
Actually John Hammond has a bot scanning this exact channel and when you say John Hammond he gets pinged and often looks at the message quietly
))
Seriously
Donating computer power to science is a nice feeling. CPU is donating to cancer research, GPU is donating to Alzheimers research, and I'm seeding Linux ISO's for freedom.

I used to run that
Damn you guys one of my phones actually had this spyware on it https://www.brinztech.com/breach-alerts/brinztech-alert-unremovable-spyware-appcloud-found-on-samsung-devices-poses-regional-security-risk/
Because i bought it in vietnam
I got Folding@Home for Alzheimers on GPU
BOINC is on Cancer on CPU
Nice one
I hate phones so goddamn much
why
ring ring ring
And of course, you gotta seed those Linux ISO's
banana phone

imagine using an app named Cash
I dont really use it that much its left over from asia times
Imagine using an app named app 
im weird and stick to Zelle
I use personal checks
Well yeah
i have never once Written, or been given a cheque
Why would you pay a middle man if you can just write a check
Thats what zelle is for...
its built into banks apps.....
Okay but then your transaction is broadcast to credit agencies
huh
Writing a check is something I've only seen in shows about the 60s
not anymore then using a personal cheque would
you can also use ACH
im weird and pay my rent via credit card
If you want to keep a bank account private the only way it doesnt get picked up by equifax is if you only use checks
Getting cc rewards on rent and taxes is pretty based ngl
its great for hitting sign-up bonuses too
helped me hit the $8k spend for amex plat π
that was a rough one
Fancy
honestly only reason i could hit it was rent tbh
When i was churning i met my minimum spend by renting airbnbs monthly instead of renting
i dont get how that maths
since wouldn't you be spending more?
as short term rentals cost more
I would snipe new users and get that 40% discount on top of the monthly discount. Sometimes id only pay 300 dollars a month
I pay with normal bank transfer
Yeah, EFT or ACH is common
What is wrong with that?
You have to be good at it to save money doing that but at least i never had to furnish an apartment or sign a lease to a slum lord
i just get enough points out of it that i can use at a high enough rate to make it a positive value
since i can get 3-4cpp on amex MR
And usually people are happy to see me and id have a kitchenette or something
To pay rent is not recommended to use cash
or atleast get a receipt if you do
Debit card
ACH
Nowadays id just car camp instead of renting
Keeping a healthy credit card payment / repayment helps build credit score too, and if you pay before interest rolls in there's no difference between just using a debit
you can just put $10 netflix on a card though
and it'll report the same
Way less stress than being a wagie
Keeping a healthy credit balance impacts credit score in the UK
e.g. over / under utilisation has an impact
it doesnt matter how much you spend, just that its paid
Use nitro to pay

does it have a history?
It does in the UK
here util is counted, but it has no history
so you just pay down 30-45 days before a new credit application
and running a high balance is good sometimes for CLIs
e.g. if you have a Β£10k credit and don't use it, that is a negative
wtf?
If you have a 10k and use 8k often, that's negative
Really thats dum
If you have 10k and keep it around 10-20%, that's positive
thats dumb af
Shouldnt it be low % util
Nah
i have like, 80k in total credit extended and i barely touch any of it
They want people to use the credit, but be able to pay it without trouble
bar a few cirmcumstances
No usage, no value, too much, big risk
Isnt there a better benefit to use credit card instead of debit?
Just right amount, means low risk value
Thats why I use credit
Fraud protection
Rewards
Yeah I was right
Yes, THIS
Flexibility with expenditure
Purchase Insurance is also 10/10
Can a credit
Well yee if they get your info they are stealing bank money not yours
not true these days
Cause i can let my capital sit in a HYSA doing earning interest until its due
Can't charge my debit card either since I have 0β¬ on it
rather then it go out right away
your out the money until its finished
unlike with credit you get instant credit
Fraud protection πͺ
Went back to reply about HTB staff if they are mostly UK, but can't see who said it now
But the answer is no
Majority is GR, but we have staff globally
Honestly for me the biggest + is the purchase protection
if i break/lose/stolen something its just covered
my bank will refund any disputed claims immediately
I did not expect that the land I live invented hackthebox
I am proud 
Cool
ive never had to do it on debit so π€·
No drinks for me tonight. I had allergy stuff
just what ive heard
my only chargeback exp is with Amex
and theyre great to deal with
.
Return protection is also kinda cool
return items to CC company if its after return period
Community meetups are that.. community
They are public, anyone can join them
Omster π
Omster π
Ohh yeah.. Im stupid lol
All good, me too sometimes
No
@terse dirge just committed cyberterrorism on my neighbours wifi
Dang
There are many in person meetups people organise
@terse dirge that is too much
Really?
Didnt find any now
Yes, we get shown photos and feedback from awesome meetup hosts frequently
Do you guys participate in them too?
imagine if it was "feetup" instead
I need them 
Staff do attend when able or arranged yes
Dope..
but I'm not really involved in that side of things, I'm just saying what I see
Even british ones or other countries in gr too?
Whenever they are able or it is arranged
its mostly community ran/lead
That's dope..
yarp
When in Spain?
Can I dm?
Suggestion: Have a search feature. Or atleast have an upcoming event show up first, Cause Quebec Canada came up first and that ended. But the one in Switzerland is next upcoming and you have to scroll all the way over to know that
/feedback 
What have you done with his neighbors wifi 
made everything redirect to cat videos
Not sure why we aren't linking there anymore on the website
That's even more clear...
Hallicon π
?
God i am suffering from this weird virus now for like 3 days phlegm, bloody mucus, and now bloodshot eyes. I have no idea what it is but it's a respiratory virus
Why arent you linking this website I mean
It's even more clear than the previous one
Dang, time to update the kernel
Could be it's in the TODO after changes to the website
So what do you do on the Cyber training gamified?
I'll mention it internally anyway
Get better man πͺ 
I look like i caught a virus from africa or the islands this shit isnt normal
Thanks
Remember to stay hydrated
I never had a respiratory virus that affected my eyes though its pretty scary but ive been getting better
Me personally?
g0blin for the love of god
You are god's gift in this server
Time to shower outdoors with the cold wind
If I got the student subscription on HackTheBox, I would still need to pay for the exam's voucher?
πͺ πͺ πͺ πͺ πͺ πͺ wish me luck or quick death
Yes
Literally you saved me a lot of times man π₯²
All good, you're welcome π
I didnt know I could do the other half of those
Gonna go game for a bit before bed now, nn
Battlegrounds is actually no longer a thing..
..I've raised that internally too, I don't think it should be there
Shit. That's odd because if I am not mistaken HTB themselves recognize that their certs aren't recongized by employers lol
Our certs are recognized
Awwwww
And I got excited
its called discord general chat now
Why are battlegrounds no longer a thing 
I would be in the website 24/7 prolly even guru by now
lmao
why dont you tell us
its obvious
Uhh, literally everybody on here talks about this. Maybe not "you", but it's not something unheard of. An example from yesterday #blue-team message
Well, everyone is welcome to their opinion
they can have my opinion too
But an opinion does not mean fact for all
If it was I wouldnt ask 
critical thinking my friend
Louder so everyone can hear it π
Besides, nowhere there did "htb recognize our certs aren't recognized"
Because if I say it they dont listen
You're just talking bs on that point
Because of toxicity maybe?
if you are playing a game, what would you define as grinding?
Hear me out
back in my day, grinding was when a girl and a guy really liked eachother and then "danced"
personally if I enjoy what Im doing and I see it as entertaining more than homework I grind even more
Are you talking about the message I referenced? You just didn't read the whole thing, this is the quotation:
Literally nobody recognized the CDSA, whenever I apply for a job they just ask me why don't you take the BTL1
Idk why you got triggered
no.... grinding is perfecting a set of instructions to optimize for time and reward
thats what happened to battlegrounds
the lack of randomness made them speedrunning problems
https://roadmap.hackthebox.com/changelog/battlegrounds-is-being-retired-on-htb-labs
All I've got for you tbh, but imho we couldn't at that time focus on building it out further, and as such usage of it was very low.. I wouldn't be surprised if we did something else in the future in the same vein
So you are saying there was an imbalance between theory and practical?
im saying that if you go up against someone at the "end game" you will get crushed by scripts
Ohhh
Mate, I was answering your question, you haven't triggered me
that makes sense
hello guys anyone did "giveback" recently ?
Oh power imbalance then
Just.. if you say something, make sure you say it in fact
Yeah that makes sense
Lol this guy reads half way through only
No I did π
You said "HTB themselves recognize that their certs aren't recognized by employers"
June 15 huh?
A month before I started cybersec
The thread you refer to doesn't show that at all
Hmmmmm wonder what my computer is doing
are you sure this wasnt ran on general today?
general?
yes, here
What you said made it sound like HTB, the company, stated that
Surely you can see the confusion?
When you guys are done I want an advice before I peace out until Friday
Well, it does show somebody talking about their experience with employers not recognizing the cert. Maybe he's not the CEO of HTB yeah, but the server is full of examples so it's not exactly the point whether they are shareholders or not. Anyway, I appreciate your clarification
omg you changed your name again...
To match it with mrholmes π₯²
But red team style
I used h0lm3s on the other one too
nvm
isnt this just fpv megabonk then?
lame
we can never have cool vr games
That's fair enough, as I said everyone has their opinion and I welcome it, and it's true not every company sees every certification in the same way, nor has every company heard of or has knowledge of every cert out there, but as a relatively new company I think we're doing pretty well.
Gonna go game for a bit, but what I'll leave you with is.. many times I've heard from community members who have fed back stating HTB, either purely due to the Labs, Academy or Certifications have directly led them in to and landed them a position in the field. When I hear that, it melts my heart.
I'm not trying to pretend we're known by everyone, nor am I saying we're the defacto in security for everyone.. there's no right answer when it comes to skills and certification
..but the fact we are helping, that's what matters
finished 4 machine through openvpn
you should be completing every machine through openvpn no?
but anyways, proud of you
So I've been stuck on noob for 2 months here, aka I made no practical progress but made a lot of academic progressπ - Which has to change. My plan is to finish the last module (Active Directories) on the Information Security Foundations path and then go to Jr Cybersec Analyst path to finish CJCA, then CPTS.. so on and so on..
Now, the question is, since Im gaining more theoretical knowledge and no practical skills, what do you recommend me to do? Im thinking either watching ippsec's easy retired boxes, or even wait it out until I'm in the penetration tester path and take months until I get practical skills to finish matchines etc etc...
I need serious help with this, like desperately 
i ran out of pwnbox
good, pwnbox is kinda not worth using (no offense g0b)
you should be running a vm of kali, parrot, or whatever OS you like
Gonna go shout at clouds
yea i was using kali iso
amazing
this was me for the past several hours vibing a burp extension into existence
was recommended virtual box
idk if thats the best but it works
What I said? I'm so confused lol
play retired machines, use the walkthrough and watch ippsec. do both.
there is nothing wrong with using a walkthrough to learn
Heylo @eternal mango
Im back
How you doing
No not you
Yeah but that's the thing that's why I came here to ask that... do I learn anything doing them with ippsec or is it gonna make me learn it "parrotish", aka do things and not understand why Im doing them??
Hey Lanex, I'm ok thanks, how're you?
you can watch ippsec do it his way and do it your way
I am doing fine
Everything I have is pure theory from academy
I think you should focus on 1 kind of box at the beginning either web or AD
Have you taken any new photos?
But that's my opinion
Also, guess what!!!!!!
this @orchid talon guy was here yesterday with practically no experience and hes already done more than you after two months, it sounds like you are lazy to me, retro
I am planning to buy a camera soon
Well it's also that I have college work burnouts and the hospital scare on the side.. π₯²
It's not really laziness
What about background
I think Im doing something wrong that's what
you cant make excuses if you want something, stop playing video games, start there
I don't play videogames π
Only one, been pretty meh this past month or two so lacking motivation, but looking forward to 3I/ATLAS being visible in late Nov/early Dec to get some shots
For me they were so last year
i doubt this greatly.
I would show you proof but I dont have any 
Plus my laptop is not a gaming
I got an FPV drone recently so got a load of videos from that, but they all have my daughter in so won't share those publicly
then you have no real excuse for why you cant do a retired machine once a day
Sooo much fun
Woah ATLAS, hope there won't be clouds to ruin it
It'll be visible through late nov and peaks in dec
so I'm sure there will be some clear nights
Understandable
Hope to be able to capture its weird glow
See that's the core of my issue... I really want to, but Idk how.. do I wait it out until I learn nmap metasploit etc from the academy? Do I watch ippsec? What if I do a retired matchine and I dont understand what I did?
I dont want to do matchines just to do them.. I want to do them and understand how I did them
why are you so timid, surely you are not like this in real life? Just fucking do it man
start the machine and work through it
Fake it until you make it
I am π
Anyway.. game time finally, before it's too late π€£ catch you later, will let you know if / when I get any decent captures

Idk if that's a weakness
Attack the machine in all holes and document how and why
the way you talk frustrates me, unconfidence is pathetic
Aight aight
I am not confident because I want the most effective way.. and that's why I asked for advice
Also i wanted to get your opinion on the cam i was buying
the most effective way is to do it... you talk about being a red teamer but you lack even a hackers mindset. at this rate you are fucked
get a grip
..fine
and i will be here to celebrate your first pwn
I'll give updated by friday 
ill hold you to it
I did all the very easy ones on my own and some without even google Im in a good start 
But the damn easy ones..
Alright thank you so much dudes
fine ill do it myself
Highly appreciate the help
Remember less yapping more hacking
someone do embedded thanos
That's why I said Im going MIA until Friday π
If I leave the server it's because Im removing distractions
good call
Everyone starts somewhere, confidence is built upon experience, it's not innate. Lacking confidence is not a sign of weakness, but it can be a driving force behind self improvement, by learning, doing, sharing.
Do what you can, learn, practice, experiment and build your own way
There's nothing wrong with standing on the backs of giants, and using knowledge shared to build your own skill set
does bradly dare to
Why are there more people like you man? 
Literally we might have the same mindset but Im on the other side of the table now
youll come to learn my tough love was necessary
I'm not thinking straight because I'm stressing about it
Yeah it damn works alright..? ππ₯\
Stressing about what? Breaking a lab ? 
Not understanding a matchine when I pwn it
ive learned nobody else will talk to you kids like i do, which is a problem. You automatically think its hostility, its truly sad
brath how good is your hardware - specifically for hashcat cracking
i just use a 4080, i hardly have to crack anything because i can extract the keys from hardware/firmware directly
Crack deez nuts
let me ask for a favour then in dm
Well now that you called me lazy you really struck a nerve but in a good way 
yeah, well you are lazy
Even tho you werent fully accurate of why you sure did a job
so prove me wrong
go for it
worst that can happen is you accidentally have 2 windows trying to dual boot into kali
Yeah true now that I think about it
I was super idle this week unlike the other weeks
Yeah.. you're right
Alright homies
Going MIA
See you in Friday
Discord absovs time
good luck
Get shit done
if i pay for vip+ does that include labs and academy?
No
bruh
Unfortunately labs and academy are totally separated
nope
Ello
not all of us are millionaires
and there is a extremely high chance you never will be
What plays in your favor is if you pay and it hurts, you'll be less likely procrastinating
Saying that inflation makes it pretty likely we'll all get there
hmmm
you have too much confidence in inflation being an in issue in the future
im more concerned about drinkable water
cant tell if this is an insult, rage bait, or idk
probably all of the above
Water shouldnt be a big problem at all with current Innovations
Breathable air bigger Problem
When we find a way to make purifying water more energy efficient it won't be. Or we just make more power
all my drinking water is going to be privatized to cool data centers running chatgpt queries about how to put your pants on and sora ai videos queries about skibadi toilet jujutsukaisen anime fights
worth
You got a point lmao
And automatic jesus
Super random question, would someone who has submitted a CVE before do a double take on my CVE write up? I'll credit you if it goes through
I think thats forbidden actually
It'd be forbidden to share it indiscriminately
That reminded me the guy that offered reviewing the whole bug bounty report before submitting
Mine is already submitted on github disclosure I just wanted someone to double check if I've missed anything